Post-quantum signatures, explained: why PQC Imza signs with ML-DSA
Quantum computers will break the signatures most software relies on today. What that means for signed documents, and how PQC Imza signs with ML-DSA, the NIST standard built to last.
3 min read
A signature on a contract is a promise that has to outlive the day it was made. A lease, a loan agreement or a shareholder resolution may be checked years later, by people who were not in the room, when the question is no longer "did you sign?" but "can you prove it?".
Electronic signatures answer that question with mathematics. The mathematics most of them use today has an expiry date.
What a quantum computer changes
Almost every digital signature in use today, whether RSA, ECDSA or Ed25519, rests on one of two problems: factoring very large numbers, or computing discrete logarithms on elliptic curves. Ordinary computers cannot solve either in any useful amount of time, and that is what keeps a signing key private even though its public half is published.
In 1994 Peter Shor described an algorithm that solves both problems efficiently on a large, fault-tolerant quantum computer. No such machine exists yet, and estimates of when one will differ widely. But the consequence for signatures is clear: once one exists, a public key would be enough to work out its private key, and whoever did so could produce signatures indistinguishable from the real owner's.
For a signed document, that is the whole problem. A signature is only evidence while nobody else could have made it.
The standard built for it
Cryptographers have spent more than a decade designing signatures that rest on problems quantum computers are not known to solve. In August 2024 the U.S. National Institute of Standards and Technology (NIST) published the first of them as standards. FIPS 204 defines ML-DSA, the Module-Lattice-Based Digital Signature Algorithm, which grew out of the CRYSTALS-Dilithium design.
ML-DSA's security rests on hard problems over mathematical lattices. It comes in three parameter sets. PQC Imza uses ML-DSA-44, the set NIST places in its security category 2, with a 1,312-byte public key and a 2,420-byte signature. That is larger than an elliptic-curve signature, but small enough to verify in milliseconds and to store alongside every document.
How PQC Imza uses it
Every signature on PQC Imza is an ML-DSA-44 signature, made on your phone with the PQC Wallet app:
- The key is born on your phone and stays there. PQC Wallet generates your signing key on the device and keeps it in the device's secure storage. Our servers only ever see the public half.
- The signature covers the document itself. What you sign includes the document's SHA-256 fingerprint. Change a single byte of the file and the signature no longer matches it.
- Every signature is checked before it counts. Our server verifies each signature against your public key, and checks that the key is the one registered to your account, before it is recorded.
- You confirm each one. Fingerprint, Face ID or your device passcode stands between the key and every signature.
When everyone has signed, the document's fingerprint and the fingerprints of its signatures are recorded on the SciChain blockchain. That record takes its time from the ledger rather than from our servers, so it can later show that these signatures existed by then.
Why act before the machines exist
It is tempting to wait until quantum computers are real. For signatures that would be too late: documents signed today with classical keys will still be around when the keys can be broken. It is much easier to sign with a quantum-resistant algorithm from the start than to re-sign an archive later.
With PQC Imza there is nothing extra to do. You sign as you would anywhere else, and the signature is post-quantum from the first day.